CVE-2026-4655 | bdthemes Element Pack Plugin up to 8.4.2 on WordPress SVG Image Widget render_svg cross site scripting
A vulnerability was found in bdthemes Element Pack Plugin up to 8.4.2 on WordPress. It has been classified as problematic. This affects the function render_svg of the component SVG Image Widget. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2026-4655. It is possible to initiate the attack remotely. There is no exploit available.
Upgrading the affected component is recommended.